CVE-2020-6843: XSS
Zoho ManageEngine ServiceDesk Plus 11.0 Build 11007 allows XSS. This issue was fixed in version 11.0 Build 11010, SD-83959.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zoho ManageEngine ServiceDesk Plusto a version that resolves this vulnerability.Fixed in 11.0 Build 11010Patch SD-83959
Event History
Frequently Asked Questions
What is the severity of CVE-2020-6843?
The severity of CVE-2020-6843 is medium with a score of 4.8.
How does CVE-2020-6843 affect Zoho ManageEngine ServiceDesk Plus?
CVE-2020-6843 allows for cross-site scripting (XSS) attacks in Zoho ManageEngine ServiceDesk Plus 11.0 Build 11007.
Has CVE-2020-6843 been fixed?
Yes, CVE-2020-6843 has been fixed in version 11.0 Build 11010 of Zoho ManageEngine ServiceDesk Plus.
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-6843?
The CWE ID for CVE-2020-6843 is CWE-79.
Where can I find more information about CVE-2020-6843?
You can find more information about CVE-2020-6843 on the following websites: [http://packetstormsecurity.com/files/156050/ZOHO-ManageEngine-ServiceDeskPlus-11.0-Build-11007-Cross-Site-Scripting.html](http://packetstormsecurity.com/files/156050/ZOHO-ManageEngine-ServiceDeskPlus-11.0-Build-11007-Cross-Site-Scripting.html), [http://seclists.org/fulldisclosure/2020/Jan/32](http://seclists.org/fulldisclosure/2020/Jan/32), [https://sec-consult.com/en/vulnerability-lab/advisories/index.html](https://sec-consult.com/en/vulnerability-lab/advisories/index.html).